Tendvane

← All articles

SecurityOctober 6, 2026

A spreadsheet that runs code when you open it, with no macro warning anywhere

Anyone who has used LibreOffice for a while has learned one reflex: if a document asks to enable macros, say no. That reflex is useless against this one. A spreadsheet built the right way can run code on your machine the moment you double-click it, and you are never asked to trust anything.

The trick stitches together three features that are each perfectly reasonable on their own. Calc lets a cell range pull data from an external database. A document can say which database driver to use. And if Java is switched on, that driver can be fetched from a web address the document chooses. Open the file and the attacker's Java code runs. It is tracked as CVE-2026-63277, it affects every LibreOffice before 26.2.5 and 26.8.0, and it was found by Rick de Jager of the V12 security team along with Thomas Rinsma and Edoardo Geraci of Codean Labs. Caolan McNamara at Collabora wrote the fix, which stops the driver path from pointing anywhere except your own disk.

Apache OpenOffice has the same problem under CVE-2026-59265, in 4.1.16 and everything before it, and there is no finished release to install yet. Version 4.1.17 is still a release candidate. The project's own advice in the meantime is to open Tools, Options, OpenOffice, Java and untick "Use a Java runtime environment". A working proof of concept has been published, so this will not stay theoretical for long.

If you run LibreOffice, update it, and do not wait for a nudge from the built-in updater. Tendvane's app update check uses winget, which has LibreOffice in it, so the newer build is one click from the same screen as the rest of your software.

Sources

Download Tendvane